AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard

A multinational company must ensure that customer data collected from users in the European Union is stored and processed only within EU-based AWS infrastructure to comply with data residency requirements. Which AWS concept primarily enables the company to meet this requirement?

  1. AEnabling AWS Shield Advanced in the EU-West-1 Region
  2. BConfiguring an Availability Zone-specific IAM policy
  3. CSelecting AWS Regions located within the EU when deploying resources
  4. DAWS Global Accelerator routing policies
Show answer & explanation

Correct answer: C. Selecting AWS Regions located within the EU when deploying resources

AWS gives customers control over where their data is stored by allowing them to choose specific AWS Regions; data does not automatically replicate to other Regions unless the customer configures it. Deploying resources in EU Regions (e.g., eu-west-1, eu-central-1) satisfies data residency requirements.

Why the other options are wrong

  • A. Shield Advanced provides DDoS protection and has no bearing on data location
  • B. IAM policies control permissions, not the physical location of stored data
  • D. Global Accelerator optimizes network routing performance, not data residency control

Data Residency via Region Selection

AWS customers control data location by choosing specific AWS Regions to deploy resources; AWS does not move customer data across Regions without explicit action.

  • Each AWS Region is a separate geographic area with multiple Availability Zones
  • Data stored in a Region stays there unless the customer replicates or moves it
  • Choosing appropriate Regions is key to meeting data residency/sovereignty laws

Memory trick: Pick your postcode — AWS keeps your data where you park it.

More Security and Compliance questions